Junglewise Threat Intelligence

CVE-2026-78448: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-78448 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Biometric Service is a system component that processes fingerprint and other biometric authentication data. A heap buffer overflow in this service allows an authenticated local attacker to execute arbitrary code with elevated system privileges, potentially compromising the security of the entire Windows system and any data protected by biometric authentication.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Biometric Service when processing specially crafted biometric data. The vulnerability requires an authenticated local attacker with user-level privileges to trigger the overflow condition. Successful exploitation allows the attacker to corrupt heap memory and execute arbitrary code in the context of the Biometric Service (which may run with higher privileges), achieving privilege escalation on the local system. A patch has been published by Microsoft as part of their security update guidance.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats